in

AG Todd Blanche: DOJ Working With X to Track Password‑Recovery Hackers

The Justice Department has publicly stepped into the mess at X after what Attorney General Todd Blanche called a “password‑recovery attack” that targeted hundreds of thousands of users. The feds say they are working closely with X to find whoever was behind the scheme. If you use the platform, this is not the time to be casual about security — and it is also a reminder that big tech must be held to account when basic protections fail.

DOJ and X coordinate on the password‑recovery attack

Attorney General Todd Blanche made it clear the Justice Department sees this as serious. He called the attackers “sophisticated cyber criminals” and said DOJ is “working closely” with X to track them down. That means federal cyber teams — and probably the FBI — are involved. Good. When hundreds of thousands of accounts are poked by criminals, we want law enforcement moving fast, not corporate spin.

How the attack worked — and why it matters

Reports say this was a password‑recovery or password‑reset attack. That means the bad actors didn’t have to crack passwords. They abused the account recovery flow to trigger reset messages, probe weaknesses, and set the stage for phishing or targeted takeovers. Even if X stopped mass hijackings, the volume alone creates risk. Platforms treat recovery as part of login security. Weak or sloppy recovery rules are an open door for cyber thieves.

X’s response and the push for accountability

X’s engineers say they found no evidence of a system breach so far and that the company disrupted the attempt. X’s general counsel also vowed to hunt down anyone who victimizes users. Fine — words are cheap. The better test is transparency: how many resets happened, how many accounts were compromised, and what fixes are being put in place. If platforms expect users to trust them, they must stop treating security like an afterthought and start acting like keepers of a public square.

What users should do and the bigger lesson

Practical steps are simple: enable two‑factor authentication or passkeys, avoid SMS‑only recovery, and treat unsolicited reset emails as red flags. Follow standards like NIST and OWASP that say recovery must be hardened and rate‑limited. But don’t let this just fall on users. The DOJ involvement is welcome, and X should be pushed to publish details and fixes so this doesn’t become a recurring punchline. Hold the platform and the criminals accountable — and tighten your own defenses while you wait for justice to do its work.

Written by admin

Leave a Reply

Your email address will not be published. Required fields are marked *

BREAKING: Jurors dismissed after chaos on sixth day of deliberations

Juror Refusal Halts Lindsay Clancy Verdict as Judge Keeps Jury Intact

GOP Voters Favor U.S. Sen. John Fetterman Over Dave McCormick

GOP Voters Favor U.S. Sen. John Fetterman Over Dave McCormick